CVE-2020-12819

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Dec 19, 2024
CWE ID 122

Summary

CVE-2020-12819 is a heap-based buffer overflow vulnerability affecting FortiGate versions 5.6.12, 6.0.10, 6.2.4, and 6.4.1, and earlier. This issue is found in the processing of Link Control Protocol (LCP) messages in FortiGate's SSL VPN daemon. A remote attacker with valid SSL VPN credentials can exploit this vulnerability by sending a large LCP packet while tunnel mode is enabled. The impact includes crashing the SSL VPN daemon, with arbitrary code execution being theoretically possible, although practically very challenging to achieve in this context.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share